
WANGUARD 5.2 User Manual & Administrator's Guide
Filter Configuration
WANGUARD Filter
was designed to protect networks
from internal and external threats (availability atacks
on DNS, VoIP, Mail and similar services, unauthorized trafc resultng in network congeston), botnet atacks, zero-
day worm and virus outbreaks. It includes sophistcated trafc analysis algorithms that are able to detect and side-
flter malicious trafc in a granular manner without impactng the user experience or resultng in downtme.
It can be deployed in-line or out-of-line by divertng the malicious trafc towards the fltering server. Trafc
diversion uses the bgpd daemon included in the quagga sofware package. An example on how to confgure bgpd
and network devices for trafc diversion is found on Appendix 3 – Confguring Trafc Diversion at page 67.
If you don't plan to use the Filter you can skip this chapter.
To manage Filters go to Confguraton » Components. The Filter Confguraton window contains the
following felds:
●
Filter Name
A short name that will help you to identfy the Filter system.
●
Interface Group
Optonal descripton used within the Console to group multple interfaces by locaton, roles etc.
●
Graph Color
The color used in graphs for the Filter. The default color is a random one, but you can change it.
●
Filter Type
Can only be “Actvated by Response”, for now.
●
Filter Server
The Server running the Filter. To add a new Server go to Confguraton » Servers » Add Server.
●
Inbound Interface
The network interface that receives the malicious trafc. If the Filter system is deployed in-line, then
this is the interface that receives the trafc entering your network.
The network interface's name must use the interface naming conventons of the Linux operatng system:
eth0 for the frst interface, eth1 for the second, eth0.900 for the frst interface with VLAN 900 and so
on. If VLANs are used then you should confgure them frst using the
vconfg
command.
●
Snifng Interface
This switch confgures the interface monitored by the Filter.
○
Inbound –
The Filter analyzes the trafc coming towards the Inbound Interface. The generated
statstcs are very accurate but the CPU usage is higher because the Filter contnuously inspects
malicious packets even if they are not being forwarded
○
Outbound –
The Filter analyzes only the trafc passing the Outbound Interface. Choosing this
- 53 -
Содержание Wanguard 5.2
Страница 1: ......